Home
LOW: 3.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:NDefault status
unaffected
11.0.0 (custom)
affected
11.1.0 (custom)
affected
11.2.0 (custom)
affected
11.3.0 (custom)
affected
12.0.0 (custom)
affected
Description
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
11.0.0 (custom)
11.1.0 (custom)
11.2.0 (custom)
11.3.0 (custom)
12.0.0 (custom)
References
docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083
docs.pingidentity.com/...s/pingfederate-120/lwu1707324350083